Connections between servers using CSS VIP?

In our new pre-production environment we have several servers connected to a 3750 switch, which is then connected to a CSS 11503. Upstream the CSS is then connected to an ASA firewall pair. The CSS VIPs are 10.22.1.0/24 on the "outside" and the servers have 10.21.1.0/24 addresses on the inside. The CSS inside & server 3750 switchports are all on the same VLAN. There is no PAT/NAT configured (except for the VIP being translated to a chosen server IP I suppose).
Whilst the clients will connect to the servers via the VIPs what we want is for each server to also be able to talk to other servers via a VIP. This is because some of the servers provide a service (LDAP actually) that we would like to be load balanced.
Now, what is curious, is that *this works* in our production environment where the servers are *directly* attached to the 8 port switch module in the CSS. However in this new environment, where the 3750 is between the servers and the CSS, it doesn't (actually you can ping the VIP sucessfully but nothing else works).
I have seen other postings on NetPro where people are trying similar things, like: http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Networking%20Solutions&topic=Application%20Networking&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1dd81312 and http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Emerging%20Technologies&topic=Content%20Networking&CommCmd=MB?cmd=display_location&location=.1dd72fd0
The relevant CSS config I think (there are lots more services etc but they are all similar) is:
circuit VLAN1
ip address 10.21.1.100 255.255.255.0
circuit VLAN2
ip address 10.22.1.1 255.255.255.0
keep alive ssokeepalive
type http
keepalive port 7777
uri "/sso/status"
keepalive frequency 10
keepalive maxfailure 2
tcp-close fin
active
service pulpldp001sso
ip address 10.21.1.6
keepalive type named ssokeepalive
active
content SSO
vip address 10.22.1.12
protocol tcp
port 7777
application http
url "/*"
advanced-balance cookie
add service pulldp001
active
i.e. VIP 10.22.1.12 will be directed to the server 10.21.1.6 (only the one shown above).
Q1) My first question is: is server to server communication via an outside VIP possible?!
Q2) Given that this seems to work our production environment without the 3750s any idea what areas of config could be wrong on the 3750 or the servers? (we've tried default routes of both the 3750 and the ISS inside address but that hasn't worked). Note the ping from a server works but when we try, say, "telnet 10.22.1.12 7777" that doesn't connect.
Q3) Let's assume that the servers run more than one service, e.g. an HTTP and an LDAP service. If a server can communicate with another server using its VIP, will it work from one server up to the CSS/VIP and back to itself? (of course it may or may not actually return to itself depending on the load etc)
I can provide full configs on Monday if required.
Hope these aren't dumb questions! Many thanks!
Simon
PS. the CSS is running 7.50 at the moment but could upgrade to 8.2 if required

Thank you Adedayo - that appears to have done the trick! I can't believe it: one little keyword!
I have to say, even once you told me the answer I still didn't find the Cisco content config manual very helpful on this point (perhaps I'm looking in the wrong place?).
Note: we're not currently doing any PAT on the CSS so don't have any source groups set up - perhaps most people do and so don't have the same problem.
I'll get chance to report back on some proper testing next week and promise to update this conversation.
Adedayo: sorry, I wanted to flag your post as solving my problem once I was sure next week but now the tick box has gone - if you reply again I'll flag that! I appreciate you taking the trouble to post.
One final question: do you have a situation where you use a VIP from a server to potentially connect back to itself? If so, does it work OK? (e.g. if you have a webserver can you connect to the content VIP that it belongs to?)
Simon

Similar Messages

  • Direct Connection between clients using sockets

    Hi, I'm a new user and i have a problem with sockets:
    The question is how can i directly connect two users that are already connected to a server in other machine???
    I mean
    user1 is connected to server
    user2 is connected to server
    user1 tries to communicate with user1 but don't want to use the server, and the server only provides the client1's ip
    I first thought to do this:
    user2 asks to server for the info of a client1-server waiting for connections, and i think it could work fine, but only if the ports are not closed by firewall, because client-server will be running in a transparent mode for user and user may not know anything about servers, sockets, ports, etc. the user only will work with a gui or something else and that's all
    Does anybody know what can i do to make this possible???
    PD
    Sorry for my bad English

    It can be implemented like you said. Make one of the clients open a serversocket and pass the ip and port number through the server to the other client with information on where to connect.
    If you're going to use direct connection between clients a lot then I would recommend that every client open a default serversocket at startup and register that information with the server and then every other client can ask the server for the ip and port to whatever client they wish to open a direct connection to.
    Be aware that clients often are behind NATs and firewalls, so if need to deal with those issues you got to use hole punching (http://en.wikipedia.org/wiki/hole_punching) - pref on a known port like 80 - and to deal with the less frequently used application firewalls you can use http encapsulation in addition.

  • Went 10.3.9 to 10.4.8 & now MacOS won't connect to Servers using afp! HELP!

    I did an upgrade installation of Mac OS 10.4.3 ontop of Mac OS 10.3.9 on a G4 AlBook. I then did the downloadable combo updater to take it 10.4.8.
    However now when I try to connect to any servers using Go - > Connect to Server I get no response.
    When I try to navigate to the Servers using the Finder and click connect I am told that the alias is broken.
    I thought his might have had to do with an installation of Netware for Mac OSX so I used the Netware install file to step through and remove all Netware files & I stil can't connect to Servers.
    Any help with this problem would be greatly appreciated.
    I have yet to run any of the software updates on top of 10.4.8 perhaps one of these improves 10.4.8 afp compatibility?
    Thanks in advance,
    Neil.

    James,
    thanks very much for this. I'd hoped not to have to go to 10.4.9 but it sounds as though your solution may well work with 10.4.8 as well? I.e. it sounds as though a component of the old system left behind by the incremental upgrade has broken the servers.
    I should have also mentioned that it is Netware boxes that I am trying to access. so it appears as though all manner of server is broken in this situation.
    This is so inconvenient (esp with regard to software authorised to hardrives, how does that behave with an archival install?).
    But once again many thanks for your help,
    Neil.

  • Exchange 2013 Outlook Anywhere connection issues when using F5 VIP

    Hello, 
    We are in the process of deploying Exchange 2013 into our Exchange 2010 Org.  We are using an F5 to load balance all services. We are doing some initial testing and have not cut over autodiscover or other URLs yet to 2013.  We are using host files
    on the local testing machines to point the URLs to 2013.    OWA, Activesync, ecp work with no issue through the F5 VIP.   However, we are having issues with Outlook.  If our host file entries point to a single server, Outlook functions
    normally.  If the host file entries point to the F5 VIP, it keeps prompting for creds and will never connect.
    Just wondering if anybody has run into this or has any guidance as far as OA and F5 deployment.
    Thanks

    Hi,
    Please check your Load Balance configuration and make sure the namespace used for Load Balance has been included in the Exchange certificate. For example: mail.domain.com and autodiscover.domain.com.
    If possible, please share your load balance configuration with us for further analysis. Here are some references about the Load Balance Scenario:
    http://blogs.technet.com/b/exchange/archive/2014/03/05/load-balancing-in-exchange-2013.aspx
    Regards,
    Winnie Liang
    TechNet Community Support

  • Connection between servers.

    Hello All,
    I need your help.
    How I can run query to connect Server 1 to server 2?
    CREATE DATABASE LINK CEN_ALL_LINK
    USING 'edidb11b';
    SELECT *
    FROM REFERENCE.REF_MOD_DESC@ALL_REF_LINK;
    This connection is not work. What I do wrong?

    If you get duplicate database link name error, you've to drop the existing link with the same name and create this new one. You can also paste your tns entry details for that TNS alias instead of using 'edidb11b'.
    CREATE DATABASE LINK <link_name>
    CONNECT TO <user> IDENTIFIED BY <pwd> USING '<tns entry>'

  • CSM module: rserver to rserver (or VIP) connections between serverfarms

    Hello,
    I am trying to audit an existing configuration of CSM module.
    Unfortunately have not an experience in CSM module configaration.
    The main goal is to understand if there are any direct connection between servers
    in different serverfarms (i.e. server from one serfarm opens session to server in
    second serverfarm to VIP or to real IP). Also I need to know if there exist any
    server initiated connection.
    For serverfarms in CSM configuration there are two options configured
    1)
    nat server
    nat client <pool>
    2)
    nat server
    no nat client
    As I understand, if there is no "static nat" lines in CSM configuration it means that
    there can not be server initiated connections. Is this correct?
    What is the best way to check if there are any direct connections between different serverfarms?
    Is it enough to take an output of "show conn" command like
        prot vlan source                destination           state      
    In  UDP  149  10.13.205.20:57944    10.36.22.20:23235     ESTAB      
    Out UDP  449  10.36.22.24:23235     10.13.205.20:57944    ESTAB      
    and check if there is "In" connection from <source IP> in one serverfarm to <destination IP>
    in second serverfarm? As for now I did not see such connections.
    Will be presented direct server-server/VIP or server initiated connections in "sh conn" command
    output for CSM module?
    Could you advise me how to check this in CSM configuration or show commands output?
    Thank you in advance.

    If the vserver to vserver connection is made between devices in the same subnet and the client uses the vsever address (rather than a vip address) then this will not be seen via the CSM at all. If the client vserver targets the vip address, then it is probable that you will require source nat to make it work. If a vserver starts a connection to another vserver addess (not vip) in a different subnet and the connection flows via the CSM,  then the CSM will show this in its connection table. You can test this via "telnet " and check the connection table. Any working vserver to vip connections will be visible in the connection table. Matthew

  • Connectivity between blades in Cisco UCS environment

    We're trying to setup a UCS environment for testing purposes, and seem to be unable to establish any connectivity between servers within the UCS. At the moment, the environment has no upstream LAN connectivity and therefore no uplinks defined on the fabric interconnects. We had wanted to run the test within the UCS keeping it isolated, and connect in via the management interface to UCS Manager. I suppose my question is, is it possible to get the blades to talk to each other without uplinks defined and connection to an external network?
    Many Thanks - Lee

    Further to what has been mentioned, you can stay in end-host mode but change the behaviour for no uplinks, which is the Network Control Policy.
    Not sure where it is on the GUI (it may be CLI only) but its described at http://ciscosystems.com/en/US/docs/unified_computing/ucs/sw/cli/config/guide/1.0.2/CLI_Config_Guide_1.0.2_chapter15.html
    The config item is
    set uplink-fail-action {link-down| warning}
    The description is
    Specifies the action to be taken when no uplink port is available in end-host mode.
    Use the link-down keyword to change the operational state of a vNIC to down when uplink connectivity is lost on the fabric interconnect, and facilitate fabric failover for vNICs. Use the warning keyword to maintain server-to-server connectivity even when no uplink port is available, and disable fabric failover when uplink connectivity is lost on the fabric interconnect. The default uplink failure action is link-down.
    When you have no uplinks all the NICs look down! This is by design. Remember you have a fabric A and a fabric B. When you have a fabric that gets isolated do you want it to fail the Ethernet links so that the blades know about it and the network failover software in your OS can send the data over the working fabric. Or do you want your blade to not know and keep sending data out, but if its destined for outside the environment its not going to get there.
    Hopefully that adds some more clarity to your situation.
    Rodos

  • Connecting redundant servers to redundant CSS

    Hi,
    I'm quiet new with CSS configurations and currently working on an assignment to get two servers (with both a redundant network connection) connected directly to a redundant CSS configuration. I have tried a box-to-box redundancy configuration but i'm having some problems with the fallback and inside connectivity. When i look at all the configuration guides and tips then there's always a switch connected between the CSS and the servers. Before i ask for help with this config i want to know if the design that they've put me up with can work! Attached there's a picture of the design. The servers have teaming enabled with fail-over option. When the primary CSS fails, the secondary CSS will take over. The primary link of the server will fail and perform a fail-over to the secondary link. I have my doubts that this design will work.
    I hope that someone can get me started :)
    Kind Regards,
    Daniel

    We have seen too many issues in the past with servers using redundant interfaces.
    We always end up recommending not to use such a solution and to insert at least 1 switch between the CSS and the servers.
    Gilles.

  • Difference between using app server connection pooling and using the driver

    Hi all,
    How to get connection pooling with out application server and tomcat also?
    What is the difference between using app server connection pooling and using the driver supported connection pooling?
    Regards,
    Murali

    maybe the performance of App server pool is better than the JDBC pool,
    for you don't know wether the implementation of the JDBC interface is good or bad.

  • Open connections between AS Java and AS ABAP when using JRA

    Hi, we have a problem with open connections and hope that someone here could give me hint where to find a solution.
    The situation is that we open a connection from a Java application to an AS ABAP. In detail, the application first connects to a statefull session bean on the AS Java by RMI. The bean communicates with the associated AS ABAP by the Java Resource Adapter (JRA).
    All interactions between all components work correctly. But even after we close the application, manually close of the connections (on side of the AS Java) , remove all created and used session beans there are still open connections between the AS ABAP and the AS Java.
    The transaction smgw (Gateway Monitor) shows open connections from jlaunch to our local SAP gateway using the internal communication protocol. Obviously, the established connections are not closed, even when they are open for a week or longer.
    After opening 100 connections, the AS ABAP denies additional connection attempts.
    We have been able to close all open connections by restarting the AS Java or by restarting the Connector over the Visual Administrator (path: Cluster – Server – Services – Connector Container – “select the right connector” – stop / start).
    We have developed our application similar to the tutorial from [https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/ad09cd07-0a01-0010-93a9-933e247d3ba4]
    Can someone explain to us why the connections stay open for so long? Is there no timeout mechanism? Or is there some way to close the connections from our Java application?

    Hello,
    maybe someone can help us with our problem.
    We have developed our application similar to the tutorial from https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/ad09cd07-0a01-0010-93a9-933e247d3ba4 and it was running without problem with the SP12, now we change our system to SP16 and we are having the problem described in note 1083348, but as you can see, for us it was working with SP12 and now it doesn't work with SP16....
    Here is part of our code....
        public List getAll() {
            String functionName = "bla";
            try {
                openConnection();
                MappedRecord response = (MappedRecord) interaction.execute(null, request);
                MappedRecord record = (MappedRecord) response.get("E_S_RETURN_CODE");
                if (((String) record.get("RETURN_CODE")).equalsIgnoreCase("E")) {
                    throw new SQLException((String) record.get("RETURN_TXT"));
            catch (ResourceException exc) {
                throw new EJBException(".");
            catch (SQLException exc) {
                throw new EJBException(".");
            finally {
                closeConnection();
        protected void openConnection() {
            try {
                connection = connectionFactory.getConnection();
                interaction = connection.createInteraction();
            catch (ResourceException exc) {
                interaction = null;
                connection = null;
                throw new EJBException(getExceptionText(exc));
      protected void closeConnection() {
           try {
                if (interaction != null) {
                    interaction.close();
                if (connection != null) {
                    connection.close();
            catch (ResourceException exc) {
                throw new EJBException(".");
    With that code we are getting this error: "Connection handle is already closed and no longer associated with a managed connection" everytime we try to close the connection in the method closeConnection().
    We were thinking that maybe we should not close the connections, because the were already close, and tried not to close the connection (connection.close()), but then after a few time we are getting the following error, because we are not closing the connections:
    Connection to ABAP System could not be opened, because the Connection Factory returns "Cannot get connection for 120 seconds. Possible reasons: 1) Connections are cached within SystemThread(can be any server service or any code invoked within SystemThread in the SAP J2EE Engine), 2) The pool size of adapter "eis/..." is not enough according to the current load of the system or 3) The specified time to wait for connection is not enough according to the pool size and current load of the system. In case 1) the solution is to check for cached connections using the Connector Service list-conns command, in case 2) to increase the size of the pool and in case 3) to increase the time to wait for connection property. In case of application thread, there is an automatic mechanism which detects unclosed connections and unfinished transactions.". Please check the connection defined for the Connection Factory of the Java Resource Adapter with JNDI name...
    Any help?

  • I have an IPad mini WiFi (not cellular) and an IPhone 5. I use the bluetooth connection between both devices when on the road. I downloaded a navigation system on my IPad using GPS positioning. Is Bluetooth OK to use GPS positioning on the IPad?

    Hi
    I have an IPad mini WiFi (not cellular) and an IPhone 5. I use the bluetooth connection between both devices when on the road. I downloaded a navigation system on my IPad using GPS positioning. Is the Bluetooth connection working to use GPS positioning on the IPad using IPhone 5 as the hotspot?
    Thanks for your input
    Felix013

    try a RESET ALL SETTINGS

  • Frustration! I have all igoods in order to use all, fully as should be. But looks like Softbank does no agree with any connection between iPhone and iMac... What in the world! How Apple let that happen???

    I live in Japan,
    I have all igoods in order to use all, fully as should be. But looks like Softbank does no agree with any connection between iPhone and iMac... What in the world! How Apple let that happen??

    Make sure that you allow pages to choose their colors and that you haven't enabled High Contrast in the Accessibility settings.
    *Firefox > Preferences > Content : Fonts & Colors > Colors : [X] "Allow pages to choose their own colors, instead of my selections above"
    See also:
    *http://kb.mozillazine.org/Images_or_animations_do_not_load
    *https://support.mozilla.org/kb/Images+or+animations+do+not+show

  • Connecting between labVIEW and PLC S7-1200 using EPICS

    Hello everyone,
    I'm trying to connect between LabVIEW and PLC S7-1200 using EPICS. I did it using OPC and it succeeded and the communication was done, so right now i'm trying to do it using EPICS. so Can anyone help me with that?
    Thanks in advance.
    Ahmed

    Hello,Ahmed:
    Now I'm trying to conect S7-1200 to Labview by OPC server 2012, I'm newer for both PLC S7-1200 and OPC server. by the help file of NI's OPC I tested many times, but lost totally.
    You mentioned that you have succeeded making the connection between them, could you please help me :
    1) How to set in Simense TIA software? I can set the PLC's IP address now, that's all;
    2) OPC server setting.
    if there is a video, that will be great.
    thanks a lot.
    Delphi77.

  • Hello, may I change data between iPad Air and other devices by cable connection (USB), (not using cloud) ?

    Hello, may I change data between iPad Air and other devices by cable connection (USB), (not using cloud) ?

    Do you mean you want to sync or transfer data using a cable? Between and iPad Air and what "other device"?

  • Is is possible to use a netgear wireless router to share a cable internet connection between an airport express and a Sony BD player?

    Hi,
    I have a couple of netgear wireless routers (WGR614, WPN824 v3) as well as a Belkin wireless router (F5D8233-4v3) lying around, and was wondering if it is possible to use any of these to share the internet feed from a cable modem to both an airport express and a Sony Blu-Ray Player?  I connected the WPN824 router between the cable modem and the airport express but the airport express will only give an orange light then as if it does not have internet access.  Any suggestions would be much appreciated! Many thanks.

    What you are basically attempting to do is extend the Belkin router with the AirPort Express Base Station (AX) via a wireless connection between them. This method is known as a Wireless Distribution System (WDS). Unfortunately, WDS is not a standard and router manufacturers implemented, in most part, to only work with their products ... so it will be very unlikely that you can create a WDS between your Belkin and the AX. There have been a few Belkin model that have been updated by third-party firmware that support WDS, but the models you listed are not any of them.

Maybe you are looking for